24/7 Support Available
Skip to main content
Beginner
2 to 4 weeks

Cyber Essentials Certification Guide

What you need in place to pass the UK Cyber Essentials assessment, covering the five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

Prerequisites

  • A list of everything in scope: laptops, desktops, mobiles, servers, and any personal devices used for work.
  • Every cloud service you use to store or process organisational data, such as Microsoft 365 or Google Workspace.
  • Administrative access to your firewalls, devices and cloud consoles so settings can be checked and changed.
  • One named person to own the assessment and gather evidence from across the business.

Step-by-Step Instructions

Set your scope

By default Cyber Essentials covers the whole organisation. You can certify a clearly separated part of the business instead, but only if a firewall or VLAN divides it from the rest. Decide this first, because scope shapes every answer that follows. Include all internet facing devices, all end user devices, and all cloud services that hold your data.

Tip

Home workers are in scope. Any device used to reach organisational data from home counts, even when the broadband router belongs to the employee.

Firewalls and internet gateways

Put a correctly configured firewall between every device and the internet. That means the boundary firewall at the office and the software firewall on each laptop that leaves it. Change default administrative passwords, block inbound connections you have not approved, and remove rules you no longer use.

Secure configuration

Vendor defaults are built for convenience, not security. Remove software and accounts you do not need, disable features that are switched on but unused, and require a PIN or password to unlock each device. The aim is a smaller attack surface on every device and service in scope.

Security update management

Everything in scope must still be supported by its vendor and receiving security updates. Turn on automatic updates where you can, and apply critical and high risk patches within 14 days of release. Retire any software or operating system that has reached end of life, because unsupported kit fails the assessment on its own.

Tip

The 14 day rule applies to updates the vendor marks critical or high risk, or that fix a vulnerability scoring 7 or above on CVSS v3.

User access control

Give people only the access their role needs, and keep separate administrator accounts that are used for admin work alone. Remove accounts quickly when someone leaves or changes job, and keep a record of who holds admin rights. Multi factor authentication is required on all cloud services and on every administrator account.

Malware protection

Protect every device using one of the accepted methods: anti malware software, application allow listing, or sandboxing. For most small organisations the protection built into a modern operating system is enough, provided it is switched on, kept current, and scanning files as they are opened.

Complete the assessment and plan for Plus

Work through the self assessment question set honestly and submit it through a certification body. If a supplier or contract asks for a hands on audit, Cyber Essentials Plus tests the same five controls with an assessor, usually within three months of your basic certificate. Treat the questionnaire as a yearly health check, not a one off.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our compliance & certification team is here to help. Talk to us about your requirements.